90 Days Gen AI Risk Trial -Start Now
Book a demo
Chatbots·Free; Pro $17-20/mo; Max from $100/mo; Team $20-25/seat/mo; Enterprise custom·claude.ai

Claude

Anthropic's conversational AI assistant built around the Claude model family, known for long-context reasoning, coding (Claude Code), and Constitutional-AI safety tuning.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Claude is Anthropic's conversational AI, positioned as a safety-forward alternative to ChatGPT. It covers writing, research, analysis, agentic tool use, and software engineering via Claude Code, with an industry-leading context window and strong coding benchmarks. Available in Free, Pro, Max, Team, and Enterprise tiers, plus the Anthropic API. Team and Enterprise include SSO, audit logs, a DPA, SOC 2 Type II and ISO 27001 coverage, and a HIPAA-ready path. Since September 2025, consumer Free/Pro/Max plans default to training on user chats with a 5-year retention window unless the user opts out.

Risk factors

3
  • Cloud-based with potential data exposure.
  • User data may be used for model training.
  • No clear opt-out for data usage.

Recommendations

8
  • Move all business usage to Claude Team or Enterprise, where Anthropic contractually does not train on inputs or outputs
  • Enforce SSO and domain capture to pull employee-created consumer accounts into the managed workspace
  • For any PHI workflow, require Claude Enterprise with a signed BAA; block consumer claude.ai for clinical staff
  • Publish guidance that 'Help improve Claude' must be toggled off on any personal account used for work, and audit where feasible
  • Disable or gate computer-use and MCP tool access until the specific agent, scopes, and data paths are reviewed
  • Use DLP to flag uploads of source code, customer PII, and financial data to claude.ai
  • Review Anthropic's sub-processor list and data residency options before moving EU or regulated workloads
  • Wire Claude Enterprise audit logs and Compliance API into the SIEM

Data handling

Storage
Stored in Anthropic's cloud infrastructure (AWS and Google Cloud) with US and EU regions; Enterprise offers additional residency controls.
Retention
Consumer Free/Pro/Max: up to 5 years if the user opts in to training, otherwise 30 days. Team/Enterprise/API: customer-configurable, with 30-day default for inputs and outputs.
Training on inputs
Consumer Free/Pro/Max train on user data by default (opt-out). Team, Enterprise, Claude for Work, Claude for Government, Claude for Education, and API usage are excluded from training by contract.